Junglewise Threat Intelligence

CVE-2024-48248: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

CVE-2024-48248 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2025-03-19

Technologies: Nakivo Backup, Nakivo Replication. Vendors: Nakivo.

Executive brief

NAKIVO Backup & Replication contains an absolute path traversal vulnerability in the getImageByPath function at the /c/router endpoint. An unauthenticated attacker can exploit this to read arbitrary files, which may lead to remote code execution due to the exposure of cleartext credentials in PhysicalDiscovery.

Affected products

  • NAKIVO Backup & Replication before 11.0.0.88174

Timeline

  • 2025-03-04: disclosed: Initial CVE publication and MITRE analysis
  • 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-03-19: exploited: Confirmed as exploited in the wild by CISA

Related threats